Security
For Your Most Sensitive Infrastructure.
Network data is critical infrastructure data. Lux protects it with enterprise controls and honest commitments.
Enterprise-Grade Protection
Encryption everywhere
Data encrypted in transit and at rest, across every service that touches it.
No model training
Your network data is never used to train models. Yours stays yours.
Access control
Workspace isolation, role-based access, and SSO through your identity provider.
Data control
Decide what to upload, export everything at any time, and delete on your schedule.
Tenant isolation
Every organization's data is isolated at the workspace level, by construction.
Independent review
Security posture reviewed as we grow — SOC 2 certification is in progress.
Zero Trust, Applied to Agents as Well as People
Every request is authorized on its own
Nothing inherits trust from the network it arrived on, the session before it, or the service that called it. Your organization is resolved per request, never assumed.
Deny by default
A door with no permission behind it refuses. When a deployment is not fully configured, Lux refuses rather than guessing — it will not quietly fall back to someone else’s infrastructure.
Least privilege by seat
A person or an agent gets exactly the reach their seat allows, and nothing beyond it.
Assume breach
Integration credentials are sealed with envelope encryption, API keys are stored hashed, and every governed action lands in a tamper-evident audit trail.
One Permission Model for People and Agents
An agent holds a seat
Not a backdoor. An agent instance is granted a seat with a ceiling, the same way a person is.
No escalation by proxy
An agent can never hold a permission the person who created it does not have.
Every agent action is a named verb
Fourteen engines, every verb classified by blast radius. High-radius work — customer notices, money, digging — requires a person.
Autonomy is a toggle
Per verb, role-gated, and off until an administrator turns it on.
Separation of duties
Whoever proposes a change is not whoever approves it.
A machine never files, pays, digs or promises alone
The rule the whole system is built to keep.
Run It Where Your Data Already Lives
Shared cloud
Your organization’s data isolated at the workspace level, by construction.
Dedicated tenant
Your own database and your own storage, operated by Lux.
Your own cloud
Lux deployed inside your infrastructure, with your identity provider, your model endpoint and your object store. Deployment is configuration, not a fork.
Who Processes Your Data
The services Lux relies on, and what each one handles. On a dedicated or self-hosted deployment, several of these are replaced by your own.
Vercel — application hosting
Supabase — primary database and realtime
Clerk — authentication and single sign-on
Anthropic — language models
Voyage AI — embeddings for retrieval
Upstash — caching and rate limiting
Cloudflare R2 — object and file storage
E2B — isolated compute sandboxes
Mapbox — mapping and geocoding
Sentry — error monitoring
Svix — outbound webhooks
BetterStack — uptime monitoring
Security reports: security@lux.tech
Security Questions, Answered
How does Lux define customer data?
Four kinds. Network data — your GIS, designs, splice records and as-builts. Operational data — work orders, crews, schedules and field photos. Subscriber data — the names, addresses and service records of the people you serve. And workspace content — what your team and its agents ask, and what Lux answers. All four are yours.
How does Lux keep my data private and secure?
Data is encrypted in transit and at rest, and integration credentials are sealed with envelope encryption. Every organization’s data is isolated at the workspace level by construction. Every request is authorized on its own, against the seat it came from. Subscriber and financial records sit behind data-class walls that most seats never cross, and every governed action is written to a tamper-evident audit trail.
Where is my data hosted and processed?
The shared cloud runs on Vercel for the application and Supabase for the database, with files in Cloudflare R2. On a dedicated tenant you get your own database and storage, operated by us. In your own cloud, Lux runs inside your infrastructure with your identity provider, your model endpoint and your object store — deployment is configuration, not a fork, so the region and the providers are yours to choose.
How do you respect access controls for our data?
Access follows the seat, not the person’s seniority. Roles carry a ceiling and a data class, so a field seat never reaches billing records and a marketing seat sees aggregates rather than subscribers. Contractors and subcontractors are confined sub-organizations: they see the work you grant them, never your customer or financial data, and never each other. Whoever proposes a change is not whoever approves it.
How does Lux ensure no one trains on our data?
Your data is not used to train models. We use commercial model-provider APIs under terms that exclude training on customer inputs and outputs. To be precise about what is still in flight: providers retain prompts briefly for their own abuse monitoring, and routing every call through a zero-retention path is work in progress, not something we claim today.
Can we use our own data to train a model for us?
Only on your explicit instruction, scoped to your workspace, and never shared with another customer or folded back into a shared model.
How often do you run security audits and vulnerability assessments?
Dependencies are scanned automatically on every change, and findings are tracked in an internal vulnerability register until they are closed. SOC 2 Type II certification and third-party penetration testing are part of a readiness programme that is underway and not yet complete — when they are done, this page will say so and name the date.
Certifications
Audited Against Recognized Standards
SOC 2 Type II and HIPAA certification are in progress. GDPR compliance is in place.
SOC 2
In progress
GDPR
HIPAA
In progress
Security Is Fundamental to How Lux Is Built
Encryption in transit and at rest
SSO through your identity provider
Role-based access per workspace
Full export, any time
Deletion on your schedule
SOC 2 certification in progress